Loading

How to Troubleshoot SSO Login Issues for a User in Salesforce

Publiceringsdatum: Jul 21, 2026
Beskrivning

When a user cannot log into Salesforce using Single Sign-On (SSO), the failure is typically caused by one or more of the following: the user's profile does not have SSO enabled, the Federation ID in Salesforce does not match the identifier sent by the Identity Provider (IdP), the SAML (Security Assertion Markup Language) assertion contains errors or incorrect attributes, or the IdP certificate uploaded to Salesforce is expired or invalid. This article walks through each of these areas to identify and resolve the issue.

Lösning

Follow the steps below to troubleshoot SSO login failures in Salesforce. Work through each section in order — most issues are resolved in the first two sections.

Check Profile Settings and Federation ID

  1. Go to Setup, search for Users in the Quick Find box, and open the affected user's record.

  2. Confirm the user's Profile has Single Sign-On enabled. Navigate to Setup > Profiles, open the profile, and verify the Is Single Sign-On Enabled checkbox is checked under Administrative Permissions.

  3. Verify the user's Federation ID in Salesforce exactly matches the unique identifier their Identity Provider (IdP) sends during authentication. A difference in case or whitespace will cause login to fail.

Review SSO Configuration and IdP Certificate

  1. In Setup, search for Single Sign-On Settings and open it. Confirm the Identity Provider Login URL and Salesforce Login URL match your IdP's configuration.

  2. Confirm the IdP certificate uploaded to Salesforce is valid and not expired. If expired, upload the renewed certificate from your IdP and save the SSO configuration.

  3. Examine the SAML assertion sent by the IdP during the failed login attempt for errors or incorrect attributes. Use a SAML tracing tool such as the SAML Tracer browser extension to capture the assertion.

  4. Check your Identity Provider's logs for errors related to the SSO attempt, such as attribute mapping failures or certificate signature mismatches.

  5. Test the SSO connection from the Identity Provider side to confirm it redirects correctly to Salesforce.

Test and Escalate

  1. Note: This step temporarily changes the user's login method — inform the user before proceeding. On the user's profile, temporarily uncheck Is Single Sign-On Enabled and ask the user to log in with their Salesforce username and password. If login succeeds, the issue is isolated to the SSO configuration. Re-enable the setting after testing.

  2. If all steps above have been completed and the issue persists, contact Salesforce Support with detailed logs from both Salesforce Login History and your Identity Provider.

Knowledge-artikelnummer

005389422

 
Laddar
Salesforce Help | Article